Skip to main content

Your research should reveal the subject.
Not your team.

Privacy training for research teams whose online work can expose their interests, identities, and relationships. Build habits your people can use when the work gets sensitive.

Different missions. Real privacy decisions.

Start with a task your people actually do. Adapt the examples, technical depth, and operating practices to the people—and relationships—you need to protect.

Investigate a subject without advertising your organization’s interest.

Repeated visits, signed-in accounts, shared browser setups, and document metadata can reveal the direction of a project before your team is ready to share it.

For researchers, analysts, intelligence teams, and their security leads.

Explore this use case

Map an investigation from search to document sharing. Identify which steps reveal an organization, an individual, or a connection between projects.

A research workflow with defined account boundaries, approved tools, and clear rules for handling material.

Protect the relationship between a reporter, a story, and a source.

A secure message is only one part of the workflow. Browser activity, contact discovery, shared files, and personal accounts can expose the surrounding relationship.

For newsrooms, investigative reporters, editors, and freelance collectives.

Explore this use case

Walk through a fictional source interaction: first contact, research, receiving files, collaboration, and publication. Discuss safer handoffs at each stage.

A source-handling checklist and a compartmentalized research setup that staff can explain and repeat.

Reduce the exposure a routine task creates for the people you support.

Public advocacy, sensitive casework, field coordination, and partner communications can require different identities and different levels of visibility.

For human rights organizations, advocates, nonprofits, and field coordinators.

Explore this use case

Use a fictional advocacy scenario to map affected people, observers, and consequences. Choose communication and device practices appropriate to that context.

A role-based privacy plan that accounts for partners, volunteers, staff turnover, and realistic device constraints.

Turn privacy policy into behavior your teams can actually sustain.

Access controls and endpoint protection matter. They do not, on their own, decide what a legitimate website, vendor, or signed-in service learns from a staff member’s work.

For cisos, security leaders, it administrators, privacy officers, and team managers.

Explore this use case

Select a high-exposure workflow, map existing controls, and identify privacy gaps. Design a usable baseline with exceptions, ownership, and a review cadence.

A training plan, a prioritized configuration backlog, and an operating guide your security and privacy owners can maintain.

Secure systems.
More deliberate exposure.

Your team can use patched devices, encrypted connections, and MFA while still disclosing sensitive interests through normal, authorized activity. Privacy training helps people examine what their work reveals and make better decisions within your existing controls.

NIST distinguishes privacy risks arising from data processing from risks caused by cybersecurity incidents. See the relationship in NIST’s Privacy Framework.

Who can access the system?

Authentication, patching, endpoint protection, and incident response help protect systems and information.

What does using it reveal?

Account links, browsing signals, sharing choices, retention, and vendor visibility shape the exposure of legitimate work.

One operating plan, coordinated with your IT, security, and privacy owners.

For participants

Recognize exposure, choose a suitable workflow, practice configurations, and know when to ask for help.

For your organization

Work toward a shared baseline, usable checklists, named owners, and fewer ad hoc tool decisions.

For the CISO

Connect staff behavior to operational risk. Define adoption checks, exceptions, and priorities for technical follow-up.

Practical skills, from the device to the policy.

Choose the modules that address your exposure. These are scoping options for a custom engagement; a single session focuses on an agreed subset, with time to practice.

Threat modeling & everyday OPSEC

Define what you need to protect, who can observe it, and what a disclosure would mean. Practice preparation, travel and remote-work routines, safe handoffs, and escalation when a workflow goes wrong.

Practice

Build an observer map for one routine task.

Browser privacy & attribution

Understand cookies, fingerprinting, extensions, private windows, and the difference between changing an IP address and changing what a website can recognize. Choose browsing boundaries around the work.

Practice

Compare a personal, organizational, and research workflow.

Read the foundations →

Device setup & configuration

Review browser settings, app permissions, updates, disk encryption, screen locks, backups, location sharing, and browser sync. Build an approved baseline around your operating systems and device-management requirements.

Practice

Walk through a configuration checklist on a practice device.

Privacy tools & VPN hygiene

Evaluate browsers, password managers, messaging tools, VPNs, and 404 by purpose, trust model, maintenance, compatibility, and limits. Cover connection checks, DNS and routing, disconnect behavior, and when a VPN does not solve the problem.

Practice

Choose controls for a scenario and explain what remains visible.

Accounts, identities & recovery

Separate work, personal, and sensitive-project accounts. Review password management, MFA, recovery paths, shared accounts, cloud sync, onboarding, and offboarding. Discuss when separate browser profiles are useful and where their boundaries end.

Practice

Sketch an account map and a recovery plan without sharing credentials.

Communication & information handling

Practice safer file sharing, metadata review, recipient verification, communication-channel selection, retention, and access decisions. Consider the people exposed by the workflow as well as the person operating it.

Practice

Rehearse a fictional sensitive handoff.

Policies & a privacy-centered ethos

Translate principles into practical rules for collection, consent, approved tools, retention, and escalation. Review employee privacy as well as commitments to clients, sources, research participants, and partners.

Practice

Draft a commitment and assign an owner, a practice, and a review date.

Technical & leadership briefings

Give engineers a deeper view of attribution surfaces and mitigation tradeoffs, or help leadership understand operational exposure, procurement decisions, and priorities. Adjust depth to the people making the decisions.

Practice

Explain one privacy risk in operational terms and propose the next action.

See it. Practice it. Explain it back.

A workshop moves from a recognizable situation to a decision participants can repeat. Demonstrations explain the mechanism; guided exercises turn that understanding into a habit.

  1. 01

    Map the task

    Start with a fictional workflow drawn from your team’s work. Agree on the information and relationships that matter.

  2. 02

    See the exposure

    Use demonstrations and an observer map to show what accounts, devices, browsers, and services can reveal.

  3. 03

    Practice a change

    Work through an approved configuration or a safer handoff. Explain the tradeoffs and check understanding.

  4. 04

    Make it repeatable

    Document a checklist, assign ownership, and identify follow-up work. Participants explain the workflow back in their own words.

“We turned on a VPN.
Can the site still know it’s us?”

Using a fictional research task, participants map the network route, account login, browser storage, and browser signals. They decide what the VPN changes, what remains connected, and which additional boundary the task needs.

The takeaway is a reasoned workflow decision, with its limits written down—not a score claiming that a person is anonymous.

Explore the browser fingerprinting guide →

Agree on the takeaways before we begin

A tailored checklist, configuration baseline, workflow map, recommended reading, policy draft, or follow-up action list can be included in scope. The materials and any adoption review are specified in your proposal.

A mission statement people can put into practice.

A privacy-centered ethos belongs in how your organization treats its employees, clients, sources, participants, and partners. We can help your team draft a mission statement and translate it into decisions about tools, collection, access, retention, and communication.

Policy work connects each commitment to an owner and an achievable practice. Your legal and policy owners review formal statements before adoption or publication.

Fit the session to your people.

Choose a facilitated remote session, or discuss an on-site workshop by arrangement. Delivery, location, accessibility needs, group size, and device constraints are agreed during scoping.

Team briefing

A focused introduction for staff or leadership. Shared language, relevant demonstrations, and decisions to take back to your team.

Best for: establishing a common starting point.

Hands-on workshop

Guided exercises in a demonstration environment or an agreed device setup. Participants practice the workflow and build a usable checklist.

Best for: changing a specific day-to-day practice.

Custom training series

Separate sessions for different roles, with room to revisit configuration, policy, and adoption. Preparation and follow-up are agreed in scope.

Best for: embedding practices across an organization.

Before the session

We discuss your audience, priority workflow, existing controls, and desired outcomes. We agree on prerequisites, practice environments, materials, and whether device changes are appropriate.

During and after

Participants can use fictional examples and demonstration accounts. Any real-device configuration follows your organization’s approvals; recordings and follow-up support are discussed in advance.

Taught by the person
building the tools.

Seth Honda Founder, 404 Privacy

Meet Seth →

Seth teaches computer science and literature and develops 404’s privacy tools. That combination shapes these workshops: technical mechanisms explained clearly, questions welcomed, and time to test understanding through practice.

The engineering work brings browser and network behavior into the lesson. The teaching experience helps make those details useful to people with different backgrounds—from a nontechnical staff member to the engineer maintaining the configuration.

Let your environment
inform the training.

An Attribution Risk Audit can assess recognizability across an agreed set of browsers, devices, networks, and workflows. Its findings can help prioritize which practices deserve training and which require engineering work.

An audit is a separate, optional engagement. You can book a workshop without commissioning one, or scope both around a shared operational question.

Explore the Attribution Risk Audit ↗

A few practical questions.

Are workshops available, or are all your courses still in development?

Custom organizational workshops can be scoped now. The separate self-paced course catalog is still in development; no published course enrollment is being offered here.

Does our team need technical experience?

No. We can scope a staff workshop around everyday tasks, a technical session for administrators and engineers, or a leadership briefing. The examples and depth are agreed before the session.

Can you recommend and help configure specific tools?

Yes, within the agreed scope. Recommendations start with your workflow, supported devices, existing controls, and maintenance capacity. Any installation or managed-device change is coordinated with your IT owner; a workshop does not grant access to your systems.

Will participants need to expose sensitive work or personal accounts?

We can use fictional scenarios and demonstration accounts. Sensitive client or source material, credentials, and personal account access are not needed for a training exercise. Any review of real organizational material is separately agreed during scoping.

How long is a workshop, and what does it cost?

Duration, group size, delivery, preparation, materials, and any follow-up are scoped to your needs. Send a short inquiry to discuss an appropriate format; we agree on scope, a quote, and timing before confirming a session.

Will this make us anonymous or certify compliance?

Training helps people make informed, repeatable decisions and reduce avoidable exposure. It does not guarantee anonymity or provide a compliance certification. Your legal and policy owners review any formal commitments.

Further reading & technical foundations

What should your team
feel prepared to do?

Tell us your organization type, approximate participant count, priority task, preferred delivery, and timing. A short description is enough—please leave out credentials and confidential client or source information.

  1. 01 Send an inquiry
  2. 02 Agree on scope & quote
  3. 03 Confirm your session

Privacy training for organizations

Help your team understand browser fingerprinting, digital tracking, and practical privacy controls. Tell us what your organization needs.

Please keep credentials, confidential client information, source material, and regulated data out of this public form.

Delivered by email. No mailing-list signup. Cloudflare provides spam verification. Privacy policy.

Loading spam verification…

Prefer email? honda@404privacy.com